CVE-2023-20198

● KEV CRITICAL

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Softw...

Affects 5 products across 2 vendors.

BCS10.0
CVSS 3.110.0
EPSS99.6%
Percentile100th
PatchPatched
KEV Added2023-10-16
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-420: CWE-420
◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the web UI feature of Cisco IOS XE Software allows an unauthenticated attacker to gain initial access and create a local user account. The attacker can then escalate privileges to root and deploy an implant. This poses a significant risk to network infrastructure and could disrupt critical operations, especially in industrial settings where network devices manage communication between control systems and HMIs.

BSID: BS-2023-GLOBAL-257171-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-20198?
A critical vulnerability in the web UI feature of Cisco IOS XE Software allows an unauthenticated attacker to gain initial access and create a local user account. The attacker can then escalate privileges to root and deploy an implant. This poses a significant risk to network infrastructure and could disrupt critical operations, especially in industrial settings where network devices manage communication between control systems and HMIs.
What is the CVSS score for CVE-2023-20198?
CVE-2023-20198 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 99.6%.
Is CVE-2023-20198 actively exploited?
Yes. CVE-2023-20198 is in the CISA KEV catalog (added 2023-10-16). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2023-20198?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z PSIRT: [email protected]
What systems are affected by CVE-2023-20198?
CVE-2023-20198 affects: Cisco, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation.
What NERC-CIP standard applies to CVE-2023-20198?
NERC CIP CIP-007 CIP-007-R1: CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable web management interface represents an unnecessary service on BES Cyber Assets if remote management is not required.
What IEC 62443 requirement maps to CVE-2023-20198?
IEC 62443 SR 3.5: IEC 62443 SR 3.5 (Input Validation) is directly violated. The firmware fails to validate input parameters before processing, enabling unauthorized access and privilege escalation.
Vulnerability Details
CVE IDCVE-2023-20198
BSIDBS-2023-GLOBAL-257171-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2023-10-16
Last Modified2025-10-28
ICS Relevance75%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the web UI feature of Cisco IOS XE Software. An unauthenticated attacker can exploit CVE-2023-20198 by sending a crafted HTTP request to the web interface, which allows them to gain initial access and create a local user account with normal user privileges. The attacker then leverages this account to exploit another vulnerability (CVE-2023-20273) to escalate privileges to root. With root access, the attacker can modify the file system, deploy implants, and potentially disrupt industrial processes by manipulating network configurations. The attacker must have network access to the web interface, typically reachable from the same network segment as the device.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Ios Xe
Rockwell Automation Allen-Bradley Stratix 5200 Firmware
Rockwell Automation Allen-Bradley Stratix 5200
Rockwell Automation Allen-Bradley Stratix 5800 Firmware
Rockwell Automation Allen-Bradley Stratix 5800
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1013 Days
CISA KEV● Active Exploitation Confirmed (added 2023-10-16)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict access controls on the web interface of affected Cisco devices. Restrict access to the web interface to trusted IP addresses using ACLs at the network perimeter (Purdue Level 2/3 boundary). Enable HTTPS and disable HTTP management. Consider deploying a web application firewall (WAF) to monitor and block suspicious activity.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R1
CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable web management interface represents an unnecessary service on BES Cyber Assets if remote management is not required.
IEC 62443: SR 3.5
IEC 62443 SR 3.5 (Input Validation) is directly violated. The firmware fails to validate input parameters before processing, enabling unauthorized access and privilege escalation.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-23
SHA-512 Audit Hash2896e931043d985973440e7ad50303a0d43a3470d7a42d604bd452d6decf3c5e29a960da27a2c478cc1f77d64fcaa072545d0e295e632f2e0fc9cec9b4fae6df
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2023-20198 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →